ÃÀ¹ú¾ü¹¤³Ð°üÉÌÊý¾Ýй¶ÊÂÎñÆØ¹âÔ±¹¤Êý¾Ý

°ä²¼¹¦·ò 2025-12-09

1. ÃÀ¹ú¾ü¹¤³Ð°üÉÌÊý¾Ýй¶ÊÂÎñÆØ¹âÔ±¹¤Êý¾Ý


12ÔÂ7ÈÕ £¬£¬£¬£¬£¬ÃÀ¹ú¾üʳаüÉÌMAG AerospaceÓÚ8ÔÂÏÂÑ®Ôâ·êÊý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬£¬¸Ã¹«Ë¾ËæºóÆô¶¯Ó¦¼±ÏìÓ¦²¢Í¨ÖªÊýǧÃû¿ÉÄÜÊÜÓ°ÏìµÄÓ×ÎÒ¡£¡£¡£¡£¡£¡£×÷ΪÄêÊÕÈ볬14ÒÚÃÀÔª¡¢Ô±¹¤³¬1400È˵ľü¹¤ÆóÒµ £¬£¬£¬£¬£¬MAG AerospaceΪÃÀ¹ú¾ü·½Ìṩµý±¨¡¢¼à¶½ºÍ¿úËÅ·þÎñ £¬£¬£¬£¬£¬Æä¿Í»§º­¸ÇÃÀ¹ú½¾ü¡¢Áª¹ú´¹Î£ÊÂÎñÖÎÀí¾Ö£¨FEMA£©¡¢¹ú·Àµý±¨¾Ö£¨DIA£©µÈÖ÷Ìâµ±¾Ö»ú¹¹¡£¡£¡£¡£¡£¡£ÊÂÎñÆðÒòÓÚ¹«Ë¾ÍøÂçÄÚ³öÏÖ¿ÉÒɻ¾¯±¨¡£¡£¡£¡£¡£¡£Îª½ÚÔìÓ°Ïì £¬£¬£¬£¬£¬MAG AerospaceѸËÙ²ÉÈ¡¶àÏî´ëÊ©£º¸ôÀëÊÜÓ°Ïì×ʲú¡¢½ûÓÃÓйØÕË»§¼°ÓòÃû¡¢×èÖ¹±í²¿½Ó¼û¡¢³ÁÖÃÃÜÂë²¢ÁªÏµ·¨Âɲ¿ÃÅ¡£¡£¡£¡£¡£¡£ºóÐøµ÷²éÏÔʾ £¬£¬£¬£¬£¬¹¥»÷ÕßËä½Ó¼ûÁË¡°ÓÐÏ޵ĵç×Ó´æ´¢Ó×ÎÒÐÅÏ¢¡± £¬£¬£¬£¬£¬µ«Î´·¢ÏÖÊý¾Ý±»²»µ±´¦ÖõÄÖ¤¾Ý¡£¡£¡£¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬¹«Ë¾Î´Ã÷È·Åû¶¾ßÌåй¶µÄÊý¾ÝÀàÐÍ¡£¡£¡£¡£¡£¡£Îª±£» £»£»£» £»£»£»¤ÊÜÓ°ÏìÈËÔ± £¬£¬£¬£¬£¬MAG AerospaceÌṩΪÆÚ24¸öÔµÄÃâ·Ñڲƭ¼ì²âºÍÉí·Ý͵ÇÔ±£» £»£»£» £»£»£»¤·þÎñ¡£¡£¡£¡£¡£¡£¼øÓڸù«Ë¾Ëù´¦ÐÐÒµµÄÃô¸ÐÐÔ £¬£¬£¬£¬£¬Ð¹Â¶µÄÓ×ÎÒÊý¾Ý¶ÔÍþвÐÐΪÕߺ͹ú¶È¼¶¹¥»÷ÕßÓµÓм«¸ß¼ÛÖµ¡£¡£¡£¡£¡£¡£


https://cybernews.com/security/mag-aerospace-military-contractor-data-breach/


2. ÀÕË÷Èí¼þÍÅ»ïÀÄÓÃShanya´ò°üƽ̨Ìӱܼì²â²¢½ûÓÃEDR


12ÔÂ8ÈÕ £¬£¬£¬£¬£¬¶à¸öÀÕË÷Èí¼þ×éÖ¯ÕýÀûÓÃÃûΪShanyaµÄ´ò°ü¼´·þÎñƽ̨²¿Êð¶ñÒâÔØºÉ £¬£¬£¬£¬£¬ÒÔÈÆ¹ý¶Ëµã¼ì²âÓëÏìÓ¦£¨EDR£©ÏµÍ³¡£¡£¡£¡£¡£¡£¸Ãƽ̨ÓÚ2024Ëêĺ¹ÄÆð £¬£¬£¬£¬£¬Í¨¹ý¼ÓÃÜ¡¢Ñ¹Ëõ¼°×Ô½ç˵°ü×°Æ÷¼¼Êõ»ìºÏ¶ñÒâ´úÂë £¬£¬£¬£¬£¬Ê¹ÓÐÐ§ÔØºÉÔÚÄÚ´æÖнâÃÜÖ´Ðжø²»´¥¼°´ÅÅÌ £¬£¬£¬£¬£¬´Ó¶ø¶ã±ÜÎÞÊý°²È«¹¤¾ß¼ì²â¡£¡£¡£¡£¡£¡£Sophos Security¼à²âÏÔʾ £¬£¬£¬£¬£¬Í»Äá˹¡¢°¢ÁªÇõµÈ¶à¹úÒÑ·¢ÏÖº¬Shanya´ò°üºÛ¼£µÄ¶ñÒâÑù±¾ £¬£¬£¬£¬£¬Medusa¡¢Qilin¡¢Crytox¼°AkiraµÈÀÕË÷Èí¼þ×éÖ¯¾ùÉæÆäÖÐ £¬£¬£¬£¬£¬ÆäÖÐAkiraʹÓÃÆµÂÊ×î¸ß¡£¡£¡£¡£¡£¡£ShanyaµÄÔË×÷»úÔìÔ̺¬£º½«Óû§Ìá½»µÄ¶ñÒâÔØºÉǶÈëWindowsϵͳÎļþshell32.dllµÄÄÚ´æÓ³É丱±¾ £¬£¬£¬£¬£¬Í¨¹ý¸²¸ÇÆäÍ·²¿¼°.text²¿ÃÅʵÏÖÒñ±Î¼ÓÔØ£» £»£»£» £»£»£»Ñ¡È¡·Ç³ß¶ÈÄ£¿£¿£¿ £¿£¿éÄÚ´æ¼ÓÔØÓë¹ÖÒì¼ÓÃÜËã·¨ £¬£¬£¬£¬£¬È·±£Ã¿¸ö¿Í»§»ñµÃ¡°Ïà¶ÔΨһ¡±µÄ´æ¸ù £¬£¬£¬£¬£¬¼ÓÇ¿¼ì²âÄѶȡ£¡£¡£¡£¡£¡£¸Ãƽ̨»¹Í¨¹ýŲÓÃRtlDeleteFunctionTableº¯Êý´¥·¢Òì³£ £¬£¬£¬£¬£¬×ÌÈÅÓû§Ä£Ê½µ÷ÊÔÆ÷·ÖÎö £¬£¬£¬£¬£¬ÖжÏ×Ô¶¯»¯¼ì²âÁ÷³Ì¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þÔÚ¹¥»÷Êý¾ÝÇÔÈ¡Óë¼ÓÃܽ׶Îǰ £¬£¬£¬£¬£¬³£Í¨¹ýDLL²à¼ÓÔØ¼¼Êõ½ûÓÃEDR¡£¡£¡£¡£¡£¡£³ýÀÕË÷Èí¼þ±í £¬£¬£¬£¬£¬ClickFix»î¶¯ÒàÀûÓÃShanya´ò°üCastleRAT¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ransomware-gangs-turn-to-shanya-exe-packer-to-hide-edr-killers/


3. VS Code MarketplaceÏÖ¶ñÒâÀ©´óÇÔÈ¡¿ª·¢ÕßÃô¸ÐÐÅÏ¢


12ÔÂ8ÈÕ £¬£¬£¬£¬£¬Î¢ÈíVisual Studio Code Marketplace½üÈÕÆØ³öÁ½¸ö¶ñÒâÀ©´ó·¨Ê½Bitcoin BlackÓëCodo AI £¬£¬£¬£¬£¬Óɰ䲼Õß"BigBlack"ÒÔÉ«²ÊÖ÷ÌâºÍAI¸±ÊÖ´ó¾Ö¼Ù×°ÉÏ¼Ü £¬£¬£¬£¬£¬Ä¿Ç°ÒѶԿª·¢ÕßÍÆËã»ú°²È«×é³ÉÑϳÁÍþв¡£¡£¡£¡£¡£¡£¾Ý°²È«»ú¹¹Koi SecurityÅû¶ £¬£¬£¬£¬£¬Bitcoin Blackͨ¹ý"*"¼¤»îÊÂÎñÔÚÿ´ÎVSCode²Ù×÷ʱ×Ô¶¯Ö´ÐÐ £¬£¬£¬£¬£¬ÔçÆÚ°æ±¾ÀûÓÃPowerShellÏÂÔØ¼ÓÃÜÓÐÐ§ÔØºÉ²¢´¥·¢¿É¼û´°¿Ú £¬£¬£¬£¬£¬Ð°æÔò¸ÄÓðµ²Ø´°¿ÚµÄÅú´¦Öþ籾ŲÓÃcurlÏÂÔØ¶ñÒâDLL £¬£¬£¬£¬£¬ÊµÏÖ¸üÒñ±ÎµÄ¹¥»÷¡£¡£¡£¡£¡£¡£Codo AIËäÐû³ÆÌṩChatGPT/DeepSeek´úÂ븨ÖúÖ°ÄÜ £¬£¬£¬£¬£¬µ«ÏÖʵÔ̺¬¶ñÒâÄ£¿£¿£¿ £¿£¿é¡£¡£¡£¡£¡£¡£ÕâÁ½¸öÀ©´ó¾ùѡȡDLL½Ù³Ö¼¼Êõ £¬£¬£¬£¬£¬½«ºÏ·¨Lightshot½ØÍ¼¹¤¾ßÓë¶ñÒâDLL°ó¸¿ £¬£¬£¬£¬£¬ÒÔruntime.exeÃûÒ岿ÊðÐÅÏ¢ÇÔÈ¡·¨Ê½¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þ»áÔÚ"%APPDATA%\Local\Evelyn"Ŀ¼´æ´¢ÇÔÈ¡Êý¾Ý £¬£¬£¬£¬£¬Ô̺¬¹ý³ÌÏêÇé¡¢¼ôÌù°åÄÚÈÝ¡¢WiFiÍ´´¦¡¢ÏµÍ³ÐÅÏ¢¡¢ÆÁÄ»½ØÍ¼¡¢ÒÑ×°Ö÷¨Ê½ÁÐ±í¼°¼ÓÃÜÇ®±ÒÇ®°üÊý¾Ý£¨ÈçPhantom¡¢Metamask¡¢Exodus£©¡£¡£¡£¡£¡£¡£Îª½Ù³ÖÓû§»á»° £¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»¹»áÎÞÍ·Æô¶¯Chrome/Edgeä¯ÀÀÆ÷ÇÔÈ¡cookie £¬£¬£¬£¬£¬²¢Õë¶ÔÐÔËÑË÷ÃÜÂëÆ¾Ö¤¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/malicious-vscode-extensions-on-microsofts-registry-drop-infostealers/


4. PetcoÊý¾Ýй¶ÊÂÎñ²¨¼°¶àÖÝ £¬£¬£¬£¬£¬Ãô¸ÐÐÅÏ¢ÔâÆØ¹â


12ÔÂ8ÈÕ £¬£¬£¬£¬£¬³èÎïÓÃÆ·¾ÞÍ·Petco֤ʵÉÏÖܲúÉú³Á´ó¿Í»§Êý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬£¬Éæ¼°ÐÕÃû¡¢Éç»á±£ÏÕºÅÂë¡¢¼ÝÕÕºÅÂë¡¢ÒøÐÐÕ˺š¢ÐÅÓþ¿¨/½è¼Ç¿¨ÐÅÏ¢¼°µ®ÉúÈÕÆÚµÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£¡£¡£Æ¾¾ÝµÂ¿ËÈøË¹ÖÝ¡¢¼ÓÖÝ¡¢ÂíÈøÖîÈûÖݺÍÃÉ´óÄÃÖÝ×ܼì²ì³¤°ì¹«ÊÒÅû¶µÄ˾·¨Í¨Öª £¬£¬£¬£¬£¬Õâ´ÎÊÂÎñÓ°ÏìÁìÓò¸²¸Ç¶àÖÝ£ºÂíÈøÖîÈûÖݽö1Ãû¾ÓÃñÊÜÓ°Ïì £¬£¬£¬£¬£¬ÃÉ´óÄÃÖÝ3Ãû £¬£¬£¬£¬£¬¶ø¼ÓÖÝÒò˾·¨ÒªÇóÏÔʾÊܺ¦ÕßÈËÊý¿ÉÄÜÔ¶³¬500ÈË £¬£¬£¬£¬£¬¾ßÌåÊý×ÖPetcoÉÐδ¹«¿ª¡£¡£¡£¡£¡£¡£PetcoÔÚÉêÃ÷ÖÐй© £¬£¬£¬£¬£¬Ð¹Â¶Ô´ÓÚ¡°Ä³¿îÈí¼þÀûÓÃÅäÖÃÎÊÌâµ¼Ö²¿ÃÅÎļþÔÚÏ߿ɽӼû¡± £¬£¬£¬£¬£¬¹«Ë¾ÒÑ¡°Á¢¼´½¨¸´·ì϶²¢Ö´Ðжî±í°²È«´ëÊ©¡±¡£¡£¡£¡£¡£¡£Ö»¹ÜÈç´Ë £¬£¬£¬£¬£¬¸Ã¹«Ë¾Î´»ØÓ¦¹ØÓÚ¾ßÌåÊÜÓ°Ïì¿Í»§×ÜÊý¡¢¼¼ÊõËÝÔ´ÄÜÁ¦¡¢ÎÊÌâ·¢ÏÖ¹¦·ò¼°ÉæÊÂÀûÓõȹؼüÎÊÌâ¡£¡£¡£¡£¡£¡£×÷ΪÄê·þÎñ³¬2400Íò¿Í»§µÄÐÐÒµ¾ÞÍ· £¬£¬£¬£¬£¬Petco½ö°µÊ¾ÒÑÏòÊÜÓ°ÏìÓ×ÎÒ¡°Ìṩ¸ü¶àÐÅÏ¢¡±¡£¡£¡£¡£¡£¡£PetcoÕýΪ¼ÓÖÝ¡¢ÂíÈøÖîÈûÖݺÍÃÉ´óÄÃÖÝÊܺ¦ÕßÌṩÃâ·ÑÐÅÓþÓëÉí·Ý͵ÇÔ¼à¿Ø·þÎñ¡£¡£¡£¡£¡£¡£


https://techcrunch.com/2025/12/08/petcos-security-lapse-affected-customers-ssns-drivers-licenses-and-more/


5. Tri-Century Eye CareÔâÀÕË÷¹¥»÷ÖÂ20ÍòÈËÊý¾Ýй¶


12ÔÂ8ÈÕ £¬£¬£¬£¬£¬½üÈÕ £¬£¬£¬£¬£¬ÃÀ¹ú±öϦ·¨ÄáÑÇÖݰͿËË¹ÏØÌṩÑÛ¿Æ»¤Àí·þÎñµÄTri-Century Eye CareÅû¶³Á´óÊý¾Ýй¶ÊÂÎñ £¬£¬£¬£¬£¬Ó°ÏìÔ¼20ÍòÈË¡£¡£¡£¡£¡£¡£¾ÝÃÀ¹úÎÀÉúÓ빫¼Ò·þÎñ²¿£¨HHS£©Ò½ÁƱ£½¡Êý¾Ýй¶׷×ÙÆ÷ÏÔʾ £¬£¬£¬£¬£¬¸ÃÊÂÎñÔ´ÓÚ9ÔÂ3ÈÕ·¢Ïֵݲȫ·ì϶ £¬£¬£¬£¬£¬¹«Ë¾ÓÚ10ÔÂÏÂѮͨ¹ý¹ÙÍø°ä²¼Í¨Öª £¬£¬£¬£¬£¬ÈϿɻ¼Õß¼°Ô±¹¤µÄÓ×ÎÒÓëÊܱ£» £»£»£» £»£»£»¤½¡È«ÐÅÏ¢¿ÉÄÜÔâй¶¡£¡£¡£¡£¡£¡£µ÷²éÏÔʾ £¬£¬£¬£¬£¬Ö»¹Üµç×Ó²¡Àúϵͳδ±»Ö±½ÓÈëÇÖ £¬£¬£¬£¬£¬µ«¹¥»÷Õß»ñÈ¡ÁËÔ̺¬ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£ÏÕºÅÂë¡¢Ò½ÁÆÕï¶ÏÐÅÏ¢¡¢½¡È«±£ÏÕÏêÇé¡¢Ö§¸¶¼Í¼¼°Ë°Îñ²ÆÕþÐÅÏ¢µÈÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£PearÀÕË÷Èí¼þ×éÖ¯Ðû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü £¬£¬£¬£¬£¬Ðû³ÆÇÔÈ¡³¬3TBÊý¾Ý £¬£¬£¬£¬£¬º­¸ÇÈËÁ¦×ÊÔ´¡¢²ÆÕþ¡¢ÒµÎñÎļþ¡¢µç×ÓÓʼþ¼°Êý¾Ý¿âµÈ £¬£¬£¬£¬£¬²¢¹«¿ª²¿ÃÅÎļþ £¬£¬£¬£¬£¬°µÊ¾ÒòTri-Century»Ø¾øÖ§¸¶Êê½ð¶ø²ÉÈ¡ÆØ¹âÐж¯¡£¡£¡£¡£¡£¡£Tri-Century Eye CareÔÚ֪ͨÖÐÇ¿µ÷ÒѲÉÈ¡²¹¾È´ëÊ© £¬£¬£¬£¬£¬µ«Î´¾ßÌå×¢Ã÷¾ßÌå¼¼Êõ½¨¸´Ï¸½Ú»òºóÐø·À»¤¹æ»®¡£¡£¡£¡£¡£¡£


https://www.securityweek.com/tri-century-eye-care-data-breach-impacts-200000-individuals/


6. ÃÀ¹ú¶àËù´óѧÔâÍøÂç´¹µö¹¥»÷


12ÔÂ8ÈÕ £¬£¬£¬£¬£¬°²È«¹«Ë¾Infoblox×îл㱨Åû¶ £¬£¬£¬£¬£¬2025Äê4ÔÂÖÁ11ÔÂÆÚ¼ä £¬£¬£¬£¬£¬ÖÁÉÙ18ËùÃÀ¹ú´óѧÔâ·êÓÐ×éÖ¯ÍøÂç´¹µö¹¥»÷ £¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÿªÔ´¹¤¾ßEvilginx³É¹¦Èƹý¶à³É·ÖÉí·ÝÑéÖ¤£¨MFA£© £¬£¬£¬£¬£¬ÇÔȡѧÉú¼°½ÌÖ°¹¤ÕË»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßͨ¹ýÖÐÑëÈ˹¥»÷£¨AiTM£©Õ½Êõ £¬£¬£¬£¬£¬ÔÚÊܺ¦Õßµã»÷´¹µöÁ´½ÓºóȾָÆäÓë´óÑ§ÕæÊµµÇÂ¼Ò³ÃæÖ®¼ä £¬£¬£¬£¬£¬Ä£ÄâµÇ¼Á÷³Ì²¢ÇÔÈ¡Óû§Ãû¡¢ÃÜÂ뼰ʵÏÖMFAºóµÄ»á»°cookie £¬£¬£¬£¬£¬´Ó¶øÆëÈ«½ÚÔìÕË»§¡£¡£¡£¡£¡£¡£¹¥»÷Á´½Ó¶àѡȡ¶ÌʱTinyURL¼Ù×°³ÉѧÌõ¥µãµÇ¼£¨SSO£©ÃÅ»§ £¬£¬£¬£¬£¬¼ÓÇ¿ºýŪÐÔ¡£¡£¡£¡£¡£¡£Îª¸²¸Ç×ÙÓ° £¬£¬£¬£¬£¬¹¥»÷Õ߯µÈÔ¸ü»»¹¥»÷ÓòÃû £¬£¬£¬£¬£¬²¢ÀûÓÃCloudflareµÈ·þÎñ°µ²Ø·þÎñÆ÷µØÎ»¡£¡£¡£¡£¡£¡£Infobloxͨ¹ý¶ÈÎöDNSģʽ £¬£¬£¬£¬£¬×·×Ùµ½¸Ã¹î¼ÆÖÐʹÓõĽü70¸ö·ÖÆçÓòÃû £¬£¬£¬£¬£¬³õ´Î¹¥»÷²úÉúÓÚ2025Äê4ÔÂ12ÈÕ £¬£¬£¬£¬£¬Ö¸±êΪʥµØÑǸç´óѧ¡£¡£¡£¡£¡£¡£¾Ý¹¥»÷Á¿Í³¼Æ £¬£¬£¬£¬£¬ÊÜÓ°Ïì×îÑϳÁµÄǰÎåËùѧÌÃΪ¼ÓÖÝ´óѧʥ¿Ë³×È·ÖУ¡¢¼ÓÖÝ´óѧʥ°Í°ÍÀ­·ÖУ¡¢Ê¥µØÑǸç´óѧ¡¢¸¥¼ªÄáÑÇÁª¹ú´óѧºÍÃÜЪ¸ù´óѧ¡£¡£¡£¡£¡£¡£


https://hackread.com/us-universities-domains-phishing-attacks/